发明名称 DNSSEC INLINE SIGNING
摘要 Systems and methods of performing incremental DNSSEC signing at a registry are described in which digital signature operations may be performed as part of a single transaction including DNS add, update, and/or delete operations and the like. Exemplary methods may include receiving a domain command from a requester, the domain command including an identifier of a domain. The received domain command may be executed with respect to data stored by the registry for the domain. As part of an individual transaction including the execution of the domain command, the registry may also sign DNSSEC records for the domain using a private key of an authoritative server. After the DNSSEC records have been signed, the registry may incrementally publish the signed DNSSEC records to a separate server. Exemplary methods may also include "look-aside" operations in which, for example, add, update, and/or delete operations may be executed on data stored in a registry database and reported to a requester, prior to applying digital-signatures to the DNSSEC data. After reporting that the instructions have been executed, the registry may generate a digital signature based on the add, update, and/or delete changes, and commit the digital signature to a registry resolution database.
申请公布号 EP2518970(B1) 申请公布日期 2017.03.22
申请号 EP20120002985 申请日期 2012.04.27
申请人 Verisign, Inc. 发明人 Smith, David;Gould, James;Essawi, Tarik;Blacka, David;Veeramachani, Srikanth
分类号 H04L29/06;H04L29/12 主分类号 H04L29/06
代理机构 代理人
主权项
地址